Welcome to our technology blog, where we provide you with the latest news, trends, and insights in the fast-paced world of tech. Join us on this exciting journey and discover the transformative power of technology today.
Tech enthusiast on a lifelong quest to break, build, and secure cool stuff. Known in the team as the go-to rubber duck 🦆.
0 Views
0 Views
About the author
Dương TrầnTech enthusiast on a lifelong quest to break, build, and secure cool stuff. Known in the team as the go-to rubber duck 🦆.
Tech enthusiast on a lifelong quest to break, build, and secure cool stuff. Known in the team as the go-to rubber duck 🦆.
Stay up to dateGet the latest threat intelligence, cybersecurity reports from CyStack delivered to your inbox
Comments (0)
Sign in to join the discussion
Related posts
{"success":true,"head":"<title>[Test Post] Deep Dive: Analysis of the New “BlackCat” Ransomware Variant - CyStack Blog</title>\n<meta name=\"robots\" content=\"nofollow, noindex, noimageindex, noarchive, nosnippet\"/>\n<meta property=\"og:locale\" content=\"en_US\" />\n<meta property=\"og:type\" content=\"article\" />\n<meta property=\"og:title\" content=\"[Test Post] Deep Dive: Analysis of the New “BlackCat” Ransomware Variant - CyStack Blog\" />\n<meta property=\"og:description\" content=\"The BlackCat ransomware group (ALPHV) has recently updated their encryptor payload. This analysis covers the initial infection vector, the new […]\" />\n<meta property=\"og:url\" content=\"https://blog.cystack.org/blog/2012/04/26/test-post-deep-dive-analysis-of-the-new-blackcat-ransomware-variant/\" />\n<meta property=\"og:site_name\" content=\"CyStack Blog\" />\n<meta property=\"article:author\" content=\"Techno-FunctionalProjectManager|SecurityEngineer|BackendWhisperer.\" />\n<meta property=\"article:tag\" content=\"en\" />\n<meta property=\"article:section\" content=\"FAQ\" />\n<meta property=\"og:updated_time\" content=\"2026-08-11T14:03:28+07:00\" />\n<meta property=\"og:image\" content=\"https://s.cystack.net/resource/home/content/30143252/landscape_ma_hoa_la_gi.png\" />\n<meta property=\"og:image:secure_url\" content=\"https://s.cystack.net/resource/home/content/30143252/landscape_ma_hoa_la_gi.png\" />\n<meta property=\"og:image:width\" content=\"1200\" />\n<meta property=\"og:image:height\" content=\"630\" />\n<meta property=\"og:image:alt\" content=\"Mã hoá là gì, tầm quan trọng của mã hoá dữ liệu\" />\n<meta property=\"og:image:type\" content=\"image/png\" />\n<meta property=\"article:published_time\" content=\"2012-04-26T21:11:07+07:00\" />\n<meta property=\"article:modified_time\" content=\"2026-08-11T14:03:28+07:00\" />\n<meta name=\"twitter:card\" content=\"summary_large_image\" />\n<meta name=\"twitter:title\" content=\"[Test Post] Deep Dive: Analysis of the New “BlackCat” Ransomware Variant - CyStack Blog\" />\n<meta name=\"twitter:description\" content=\"The BlackCat ransomware group (ALPHV) has recently updated their encryptor payload. This analysis covers the initial infection vector, the new […]\" />\n<meta name=\"twitter:image\" content=\"https://s.cystack.net/resource/home/content/30143252/landscape_ma_hoa_la_gi.png\" />\n<meta name=\"twitter:label1\" content=\"Written by\" />\n<meta name=\"twitter:data1\" content=\"Dương Trần\" />\n<meta name=\"twitter:label2\" content=\"Time to read\" />\n<meta name=\"twitter:data2\" content=\"5 minutes\" />\n<script type=\"application/ld+json\" class=\"rank-math-schema\">{\"@context\":\"https://schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https://blog.cystack.org/#organization\",\"name\":\"CyStack\",\"url\":\"https://blog.cystack.org\"},{\"@type\":\"WebSite\",\"@id\":\"https://blog.cystack.org/#website\",\"url\":\"https://blog.cystack.org\",\"name\":\"CyStack\",\"publisher\":{\"@id\":\"https://blog.cystack.org/#organization\"},\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https://s.cystack.net/resource/home/content/30143252/landscape_ma_hoa_la_gi.png\",\"url\":\"https://s.cystack.net/resource/home/content/30143252/landscape_ma_hoa_la_gi.png\",\"width\":\"1200\",\"height\":\"630\",\"caption\":\"M\\u00e3 ho\\u00e1 l\\u00e0 g\\u00ec, t\\u1ea7m quan tr\\u1ecdng c\\u1ee7a m\\u00e3 ho\\u00e1 d\\u1eef li\\u1ec7u\",\"inLanguage\":\"en-US\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https://blog.cystack.org/blog/2012/04/26/test-post-deep-dive-analysis-of-the-new-blackcat-ransomware-variant/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":\"1\",\"item\":{\"@id\":\"https://blog.cystack.org\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"position\":\"2\",\"item\":{\"@id\":\"https://blog.cystack.org/blog/2012/04/26/test-post-deep-dive-analysis-of-the-new-blackcat-ransomware-variant/\",\"name\":\"[Test Post] Deep Dive: Analysis of the New \\u201cBlackCat\\u201d Ransomware Variant\"}}]},{\"@type\":\"WebPage\",\"@id\":\"https://blog.cystack.org/blog/2012/04/26/test-post-deep-dive-analysis-of-the-new-blackcat-ransomware-variant/#webpage\",\"url\":\"https://blog.cystack.org/blog/2012/04/26/test-post-deep-dive-analysis-of-the-new-blackcat-ransomware-variant/\",\"name\":\"[Test Post] Deep Dive: Analysis of the New \\u201cBlackCat\\u201d Ransomware Variant - CyStack Blog\",\"datePublished\":\"2012-04-26T21:11:07+07:00\",\"dateModified\":\"2026-08-11T14:03:28+07:00\",\"isPartOf\":{\"@id\":\"https://blog.cystack.org/#website\"},\"primaryImageOfPage\":{\"@id\":\"https://s.cystack.net/resource/home/content/30143252/landscape_ma_hoa_la_gi.png\"},\"inLanguage\":\"en-US\",\"breadcrumb\":{\"@id\":\"https://blog.cystack.org/blog/2012/04/26/test-post-deep-dive-analysis-of-the-new-blackcat-ransomware-variant/#breadcrumb\"}},{\"@type\":\"Person\",\"@id\":\"https://blog.cystack.org/author/duongtt/\",\"name\":\"D\\u01b0\\u01a1ng Tr\\u1ea7n\",\"url\":\"https://blog.cystack.org/author/duongtt/\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https://secure.gravatar.com/avatar/1e188c38efc1c39f1c24f2a3c694c3c9452f2dee05fa635e6c094c391c7e1c14?s=96&d=mm&r=g\",\"url\":\"https://secure.gravatar.com/avatar/1e188c38efc1c39f1c24f2a3c694c3c9452f2dee05fa635e6c094c391c7e1c14?s=96&d=mm&r=g\",\"caption\":\"D\\u01b0\\u01a1ng Tr\\u1ea7n\",\"inLanguage\":\"en-US\"},\"sameAs\":[\"Techno-FunctionalProjectManager|SecurityEngineer|BackendWhisperer.\"],\"worksFor\":{\"@id\":\"https://blog.cystack.org/#organization\"}},{\"@type\":\"BlogPosting\",\"headline\":\"[Test Post] Deep Dive: Analysis of the New \\u201cBlackCat\\u201d Ransomware Variant - CyStack Blog\",\"datePublished\":\"2012-04-26T21:11:07+07:00\",\"dateModified\":\"2026-08-11T14:03:28+07:00\",\"author\":{\"@id\":\"https://blog.cystack.org/author/duongtt/\",\"name\":\"D\\u01b0\\u01a1ng Tr\\u1ea7n\"},\"publisher\":{\"@id\":\"https://blog.cystack.org/#organization\"},\"description\":\"The BlackCat ransomware group (ALPHV) has recently updated their encryptor payload. This analysis covers the initial infection vector, the new Rust-based loader, and the specific cryptographic primitives used during the file locking process.\",\"name\":\"[Test Post] Deep Dive: Analysis of the New \\u201cBlackCat\\u201d Ransomware Variant - CyStack Blog\",\"@id\":\"https://blog.cystack.org/blog/2012/04/26/test-post-deep-dive-analysis-of-the-new-blackcat-ransomware-variant/#richSnippet\",\"isPartOf\":{\"@id\":\"https://blog.cystack.org/blog/2012/04/26/test-post-deep-dive-analysis-of-the-new-blackcat-ransomware-variant/#webpage\"},\"image\":{\"@id\":\"https://s.cystack.net/resource/home/content/30143252/landscape_ma_hoa_la_gi.png\"},\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https://blog.cystack.org/blog/2012/04/26/test-post-deep-dive-analysis-of-the-new-blackcat-ransomware-variant/#webpage\"}}]}</script>\n"}
The BlackCat ransomware group (ALPHV) has recently updated their encryptor payload. This analysis covers the initial infection vector, the new Rust-based loader, and the specific cryptographic primitives used during the file locking process.
Our team detected unusual activity originating from a compromised supply chain vendor, leading to the deployment of this sophisticated variant. Unlike previous versions, this payload utilizes an advanced obfuscation technique that bypasses standard EDR signatures.
“The shift to Rust not only provides cross-platform capabilities but also complicates reverse engineering efforts due to its unique memory management and lack of standard library dependencies.”
Olivia Rhye Senior Malware Analyst
Icon CRITICAL WARNING
New variants of BlackCat have been observed attempting to disable backups via Volume Shadow Copy Service (VSS) immediately upon execution. Ensure offline backups are regularly tested and isolated from the main network segment.
Initial Access & Attack Flow
Phishing Campaign
08:00 UTC
Targeted emails containing malicious PDF attachments sent to HR department.
Dropper Execution
08:15 UTC
User opens PDF, triggering a macro that executes a PowerShell script to download the loader.
Attackers use harvested credentials to move laterally via RDP to the domain controller.
78
Lỗ hổng được phát hiện chỉ trong vòng 2 tháng
43
Lỗ hổng được trao thưởng cho các nhà nghiên cứu
100$
Chi phí cho mỗi lỗ hổng tìm được trong hệ thống
Bảo mật dữ liệu & tính sẵn sàng hệ thống
Encrypts only the first 1MB of large files to maximize speed.
Bảo mật dữ liệu & tính sẵn sàng hệ thống
Encrypts only the first 1MB of large files to maximize speed.
Bảo mật dữ liệu & tính sẵn sàng hệ thống
Encrypts only the first 1MB of large files to maximize speed.
Technical Analysis
The core payload is heavily obfuscated. Upon decryption, we identified the following routine responsible for generating the encryption keys. The malware uses ChaCha20 for file encryption and RSA-4096 for key protection
ChaCha20 Implementation
The specific implementation of ChaCha20 used here deviates from the standard RFC 7539. It uses a modified nonce size which makes decryption without the private key impossible.
void DecryptPayload(unsigned char* buffer, int length) {
// Initializing the ChaCha20 context with the extracted key
CHACHA20_CTX ctx;
chacha20_init(&ctx, g_encryptionKey, g_nonce);
for (int i = 0; i < length; i += 64) {
chacha20_encrypt(&ctx, buffer + i, buffer + i, 64);
// Anti-analysis check: Verify memory integrity
if (IsDebuggerPresent()) {
TriggerSelfDestruct();
return;
}
}
}
The specific implementation of ChaCha20 used here deviates from the standard RFC 7539. It uses a modified nonce size which makes decryption without the private key impossible.
Decodes a Base64 string to obtain the FileList URI
Stores these files in a directory shaped to resemble a Windows Update cache path. We refer to this directory as Staging.
Marks the Staging directory with both Hidden and NotContentIndexed, reducing its visibility in normal browsing and excluding it from Windows indexing
Decodes a Base64 string to obtain the FileList URI
Decodes a Base64 string to obtain the FileList URI
Decodes a Base64 string to obtain the FileList URI
Stores these files in a directory shaped to resemble a Windows Update cache path. We refer to this directory as Staging.
Network Infrastructure
The C2 infrastructure utilizes a mesh of compromised IoT devices to proxy traffic. Below is the visualized topology of the attack network.
Figure 1: Visualized Command & Control (C2) Traffic Flow
💡 Bạn có muốn xây dựng quy trình theo dõi, quản lý và kiểm kê toàn bộ thiết bị trong công ty một cách bài bản? Hãy tham khảo tài liệu mà CyStack đã biên soạn dưới đây.
The malware employs a modular plugin architecture, separating the core encryption logic from propagation and evasion modules.
Encryption Module
The encryption module is statically linked and contains the ChaCha20 implementation. It operates independently of the C2 connection once the public key is retrieved, ensuring file locking even if the network is severed.
Encryption Module
The encryption module is statically linked and contains the ChaCha20 implementation. It operates independently of the C2 connection once the public key is retrieved, ensuring file locking even if the network is severed.
Encryption Module
The encryption module is statically linked and contains the ChaCha20 implementation. It operates independently of the C2 connection once the public key is retrieved, ensuring file locking even if the network is severed.
Figure 1: Visualized Command & Control (C2) Traffic Flow
Attack Sequence Diagram
flowchart TD
A["Initial Access"] -->|"Phishing / VPN"| B["Reconnaissance"]
B --> C["Credential Access"]
B --> D["Data ExfiltrationTo MEGA / Rclone"]
B --> E["EncryptionChaCha20 + RSA"]
classDef blue fill:#eff6ff,stroke:#3b82f6,stroke-width:2px,color:#1d4ed8,font-weight:bold
classDef neutral fill:#ffffff,stroke:#d1d5db,stroke-width:1.5px,color:#111827,font-weight:bold
classDef danger fill:#fef2f2,stroke:#fca5a5,stroke-width:1.5px,color:#dc2626,font-weight:bold
class A blue
class B,C neutral
class D,E danger
Chart Information
Reference
[1] Lin, M., Harwood, J.& Hummert, M. L. (2008). Young adults’ intergenerational communication schemas in Taiwan and the USA. Journal of Language and Social Psychology, 27(1), 28-50.
[2] Swedin, E. G. (2006, May/June). Designing babies: A eugenics race with China? The Futurist, 40, 18-21.
[Test Post] Deep Dive: Analysis of the New “BlackCat” Ransomware Variant - CyStack Blog